MERIDIAN · Critical Infrastructure · Patent Pending
$1.4M/day NERC Penalties

Real-time cryptographic audit trails for critical infrastructure.

14 NERC CIP standards. $1.4M/day in penalties for non-compliance. MERIDIAN makes every SCADA command, every access event, and every grid operation cryptographically verifiable in real time — so when auditors arrive, you don't prepare. You just show them the dashboard.

14 NERC CIP Standards CNSA 2.0 Ready CIP-015 Ready Patent Pending
The Risk

Non-compliance is not an operational risk. It's a financial one.

NERC enforcement is active and accelerating. These penalties are real, documented, and growing.

$1.4M/day

Maximum NERC penalty exposure

FERC's penalty guidelines allow up to $1.4M per day per violation for CIP non-compliance. Enforcement actions have already cost utilities tens of millions in a single settlement.

Duke Energy: $2.7M · PG&E: $10M settlement · Average enforcement up 340% since 2019
+220%

Rise in physical security intrusions since 2022

Physical attacks on grid infrastructure have surged since 2022. CIP-006 and CIP-014 require logging and attestation of every physical access event. Manual logs don't survive enforcement scrutiny.

NERC GridEx data · DHS CISA advisory AA22-265A · 2023 substation incidents
Oct 2028

CIP-015 deadline — internal network monitoring

NERC CIP-015 introduces mandatory internal network security monitoring requirements for high- and medium-impact BES Cyber Systems. Utilities have no compliant tooling today. The deadline is October 2028.

NERC CIP-015-1 · FERC Order 887 · Effective enforcement Q4 2028
What MERIDIAN covers

Every operation. Signed. Immutable. Court-admissible.

Six capability areas that together cover every NERC CIP evidence requirement an auditor can ask for.

SCADA Command Logging

Every grid operation — breaker operations, setpoint changes, load shedding commands — generates an ML-DSA-65 signed receipt in real time. No operation goes unwitnessed.

ML-DSA-65 · FIPS 204 · per-command

Access Control Attestation

Every badge swipe, electronic login, and physical access event is cryptographically logged with identity, timestamp, and authorization context. CIP-004 and CIP-006 covered.

CIP-004 · CIP-006 · identity-bound

Security Event Monitoring

Real-time alerts with immutable evidence chain. Every anomaly — unauthorized access attempt, configuration change, network intrusion — is logged, signed, and time-stamped before alerting.

CIP-007 · CIP-008 · CIP-015

NERC Compliance Dashboard

Single pane showing compliance status across all 14 CIP standards. Auditor-ready export in one click. Gap analysis auto-updated as your environment changes.

14 CIP standards · real-time · exportable

Post-Quantum Security

All signatures use ML-DSA-65 (CRYSTALS-Dilithium), NIST FIPS 204 selected. CNSA 2.0 ready, future-proofed for the 2030 NSA post-quantum mandate. Records signed today remain verifiable in 2040.

CNSA 2.0 · FIPS 204 · 2030 mandate ready

Offline Verification

Auditors verify any evidence package without network access in 8.6ms. Self-contained signed receipts require no Hive infrastructure, no API call, no internet connection. Air-gapped environments supported.

8.6ms · offline · air-gap ready
NERC CIP Coverage

All 14 standards. Every requirement mapped.

MERIDIAN generates evidence for every NERC CIP standard in scope. No gaps, no manual log exports, no last-minute audit preparation.

CIP-002
BES Cyber System Categorization
CIP-003
Security Management Controls
CIP-004
Personnel & Training
CIP-005
Electronic Security Perimeter
CIP-006
Physical Security of BES
CIP-007
Systems Security Management
CIP-008
Incident Reporting & Response
CIP-009
Recovery Plans for BES
CIP-010
Config Change Management
CIP-011
Information Protection
CIP-012
Communications Between Control Centers
CIP-013
Supply Chain Risk Management
CIP-014
Physical Security of Transmission
CIP-015
Internal Network Security Monitoring · Oct 2028
Compliance Dashboard

When auditors arrive, you show them this.

MERIDIAN's compliance dashboard gives you real-time posture across all 14 CIP standards. Every number is backed by a cryptographically signed evidence chain.

meridian.thehiveryiq.com · NERC CIP Compliance Dashboard LIVE
14 / 14
CIP Standards Covered
100%
SCADA Commands Signed
8.6ms
Avg Verification Time
0
Open Audit Gaps
NERC CIP COMPLIANCE POSTURE
14 / 14 standards · AUDIT READY
Deployment

No rip-and-replace. Sidecar deployment in four weeks.

MERIDIAN integrates with your existing OT security stack. Your SCADA systems are untouched. Your auditors see results in 30 days.

Integrates with your OT security vendors

MERIDIAN is a cryptographic attestation layer, not a replacement. It plugs into the OT security infrastructure you already operate.

Dragos Claroty Nozomi Networks Fortinet OT Cisco CX
Sidecar architecture — existing SCADA systems, PLCs, and HMI platforms remain fully unchanged. MERIDIAN observes and signs; it never routes or modifies operational traffic.
Air-gap compatible. Works in classified, disconnected, and physically isolated BES environments. No internet dependency for operational logging.

From contract to audit-ready in 4 weeks

  • W1
    WEEK ONE
    SCADA logging active
    MERIDIAN sidecar deployed. All SCADA commands begin generating ML-DSA-65 signed receipts. Real-time signing verified.
  • W2
    WEEK TWO
    All 14 CIP standards covered
    Access control, physical security, and network event logging active. Dashboard shows live compliance posture across all CIP standards.
  • W3
    WEEK THREE
    Evidence library built
    30 days of signed evidence accumulates. Gap analysis complete. Any open findings surfaced and remediation paths documented.
  • W4
    WEEK FOUR
    First NERC audit readiness package
    Complete audit package exported: signed evidence, CIP-by-CIP coverage report, gap remediation log, and offline-verifiable receipt bundle.
Comparison

Manual logs won't survive a NERC audit.

See why existing approaches leave utilities exposed — and what MERIDIAN does differently.

Capability Manual Logs + Spreadsheets Existing NERC Tools MERIDIAN
Real-time attestation Manual, delayed Batch, next-day Sub-second, every event
Post-quantum signatures None None ML-DSA-65 / FIPS 204
Court-admissible evidence Disputed in enforcement Partial Cryptographic, tamper-evident
CIP-015 ready Not addressed Partial roadmap Fully covered
Offline verification N/A Requires connectivity 8.6ms, air-gap ready
Cost per signed event Immeasurable liability $0.08–$0.40 Fixed annual — $150K/yr
Audit package generation Weeks of manual work Days, manual export One-click, instant
SCADA command logging Incomplete, mutable Vendor-dependent 100%, cryptographically signed
Who uses MERIDIAN

Three buyer profiles. One urgent problem.

NERC enforcement affects every regulated utility. These are the organizations that move first.

Best first customer

Utility under active NERC enforcement

You've received a Notice of Penalty or a compliance violation finding. Your legal team is managing the settlement. You need defensible evidence going forward — and you need it fast.

Why MERIDIAN fits
  • Immediate audit trail from day one
  • Cryptographic evidence withstands scrutiny
  • Pilot ROI visible within 30 days
RTO / ISO

Regional transmission operator managing multi-utility compliance

You coordinate reliability across dozens of member utilities. Each has its own NERC CIP posture, its own audit cycle. Aggregating evidence from all of them is a manual nightmare every quarter.

Why MERIDIAN fits
  • Multi-entity compliance dashboard
  • Cross-utility evidence consolidation
  • CIP-012 inter-control-center coverage
CIP-015 Preparation

Utility preparing for CIP-015 before October 2028

CIP-015 internal network security monitoring requirements are finalized. The compliance date is October 2028. Most utilities have no tooling that generates the required evidence today. The window to build it is closing.

Why MERIDIAN fits
  • CIP-015 evidence built in from day one
  • FERC Order 887 compliance pathway
  • Deploy now, audit-ready before 2028
Get started

When NERC auditors arrive, you don't prepare. You show them the dashboard.

$150,000/year. $1.4M/day is the alternative.

Pilot deployment in four weeks. Full CIP coverage. Fixed annual cost. No per-event billing. No infrastructure to operate.

Patent Pending · CNSA 2.0 · FIPS 204 · CIP-015 Ready · ML-DSA-65